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AMENDMENTS TO THE CLAIMS: 

This listing of claims will replace all prior versions, and listings, of the claims in the 
application. 

Listing of Claims: 

1 . (Currently Amended) A user information management apparatus constructed at at 
least one of (a) a server capable of making bidirectional communication with a user terminal, and 
(b) a user terminal, the apparatus comprising: 

storage means for holding user information conceming a plurality of users who use the 
user terminal to be associated with a security level; 

identification means for, when a user makes access to the server and an attempt is made 
by the user to use a predetermined application, identifying the user; 

level determination means for, when the user makes access to the server, determining at 
which of a plurality of predetermined certification levels this access is; 

transmission control means for enabling transmission of only the user information at the 
security level and the lower security level than said security level that corresponds to the 
determined level to the user terminal and/or another device among the user information held in 
the storage means; and 

transmission disabling means for, following at least one of conditions (a) an elapse of a 
predetermined period of time and/or an execution of a predetermined operation after 
predetermined user information is enabled to be transmitted by transmission control means, and 
(b) an input a predetermined instruction from the user, disabling transmission of user information 
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at security levels other than the lowest thus enabled to be transmitted. 

2. (Original) A user information management apparatus according to claim 1, wherein 
said transmission disabling means enables only user information at a security level lower than 
the security level that corresponds to the determined level to be transmitted to the user terminal 
and/or another device. 

3. (Original) A user information management apparatus according to claim 1 or claim 2, 
wherein said user identifying means uses at least one of (a) a password inputted by the user at the 
user terminal, (b) ID card information, (c) magnetic card information, (d) fingerprint, (e) 
voiceprint, and (f) iris print of the user which are read by the user terminal. 

4. (Currently Amended) A user information management apparatus according to any on e 
efclaim 1 through 3 or claim 2 , wherein said level determining means determines a 
predetermined technique employed by the user for the purpose of user identification, thereby 
determining a level. 

5. (Currently Amended) A user information management apparatus according to claim 1 
constructed at at least one of (a) a server capable of making bidirectional communication with a 
user terminal, and (b) a user terminal the apparatus comprising: storage means for holding user 
information concerning a plurality of users who use the user terminal to be associated with a 
security level; identification means for, when a user makes access to the server and an attempt is 
made by the user to use a predetermined application, identifying the user: level determination 
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means for, when the user makes access to the server, determining at which of a plurality of 
predetermined certification levels this access is; transmission control means for enabling 
transmission of only the user information at the security level and the lower security level than 
said security level that corresponds to the determined level to the user terminal and/or another 
device among the user information held in the storage means; and transmission disabling means 
for, following at least one of conditions (a) an elapse of a predetermined period of time and/or an 
execution of a predetermined operation after predetermined user information is enabled to be 
transmitted by transmission control means, and (h) an input a predetermined instruction fi-om the 
user, disabling transmission of user information thus enabled to be transmitted, wherein said user 
identifying means determines said user based on a predetermined instruction fi"om an input 
device operated by said user at said user terminal, and said level determining means determines 
that the certification level is the lowest. 

6. (Currently Amended) A user information management apparatus according to claim 1 
constructed at at least one of (a) a server capable of making bidirectional communication with a 
user terminal, and (b) a user terminal, the apparatus comprising: storage means for holding user 
information conceming a plurality of users who use the user terminal to be associated with a 
security level; identification means for, when a user makes access to the server and an attempt is 
made by the user to use a predetermined application, identifying the user; level determination 
means for, when the user makes access to the server, determining at which of a plurality of 
predetermined certification levels this access is; transmission control means for enabling 
transmission of only the user information at the security level and the lower security level than 
said seciuitv level that corresponds to the determined level to the user terminal and/or another 
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device among the user information held in the storage means: and transmission disabling means 
for, following at least one of conditions (a) an elapse of a predetermined period of time and/or an 
execution of a predetermined operation after predetermined user information is enabled to be 
transmitted by transmission control means, and (b) an input a predetermined instruction from the 
usen disabling transmission of user information thus enabled to be transmitted, wherein, if a 
current certification level of the user is lower than a desired certification level required for data 
acquisition, said transmission control means instructs the user to take action required to level up 
to the required certification level. 

7. (Currently Amended) A user information management apparatus according to claim 1 
constructed at at least one of (a) a server capable of making bidirectional communication with a 
user terminal, and (b) a user terminal, the apparatus comprising: storage means for holding user 
information concerning a plurality of users who use the user terminal to be associated with a 
security level: identification means for, when a user makes access to the server and an attempt is 
made by the user to use a predetermined application, identifying the user; level determination 
means fon when the user makes access to the server, determining at which of a plurality of 
predetermined certification levels this access is: transmission control means for enabling 
transmission of only the user information at the security level and the lower security level than 
said security level that corresponds to the determined level to the user terminal and/or another 
device among the user information held in the storage means: and transmission disabling means 
for, following at least one of conditions (a) an elapse of a predetermined period of time and/or an 
execution of a predetermined operation after predetermined user information is enabled to be 
transmitted by transmission control means, and (b) an input a predetermined instruction from the 
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usen disabling transmission of user information thus enabled to be transmitted , wherein said 
transmission control means has means for defining a security level specific to said user 
information and means for managing said user information for said each security level. 

8. (Currently Amended) A user information management apparatus according to claim 1 
anv one of claims 5 to 7. wherein the apparatus is arranged to hold, in the storage means, 
information common to a plurality of users who use the user terminals as group data to be 
associated with a security level. 

9. (Currently Amended) A user information management apparatus according to claim 1 
constructed at at least one of (a) a server capable of making bidirectional commxmication with a 
user terminal and (b) a user terminal the apparatus comprising: storage means for holding user 
information concerning a pluralitv of users who use the user terminal to be associated with a 
securitv level: identification means fon when a user makes access to the server and an attempt is 
made bv the user to use a predetermined application, identifying the user; level determination 
means for, when the user makes access to the server, determining at which of a pluralitv of 
predetermined certification levels this access is: transmission control means for enabling 
transmission of onlv the user information at the securitv level and the lower securitv level than 
said securitv level that corresponds to the determined level to the user terminal and/or another 
device among the user information held in the storage means: and transmission disabling means 
for, following at least one of conditions (a) an elapse of a predetermined period of time and/or an 
execution of a predetermined operation after predetermined user information is enabled to be 
transmitted bv transmission control means, and (h) an input a predetermined instruction fi-om the 
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user, disabling transmission of user information thus enabled to be transmitted, wherein, for a set 
of requested data, an index as an ID is obtained from a distance between a probability of such an 
event and data, and then, the obtained value is used to reconfirm a security. 

10. (Currently Amended) A user information management apparatus according to claim 
4- constructed at at least one of (a) a server capable of making bidirectional conmnmication with 
a user terminal and (b) a user terminal, the apparatus comprising: storage means for holding user 
information conceming a plurality of users who use the user terminal to be associated with a 
security level: identification means for, when a user makes access to the server and an attempt is 
made by the user to use a predetermined application, identifying the user: level determination 
means for, when the user makes access to the server, determining at which of a pluraUty of 
predetermined certification levels this access is: transmission control means for enabling 
transmission of only the user information at the security level and the lower security level than 
said security level that corresponds to the determined level to the user terminal and/or another 
device among the user information held in the storage means: and transmission disabling means 
for, following at least one of conditions (a) an elapse of a predetermined period of time and/or an 
execution of a predetermined operation after predetermined user information is enabled to be 
transmitted by transmission control means, and (b) an input a predetermined instruction from the 
user, disabling transmission of user information thus enabled to be transmitted , wherein the 
apparatus is arranged so that said plurality of user terminals are classified in advance into a 
plurality of security divisions, and security division determining means is provided, thereby 
applying access restriction for such each security division of the user terminal that has made 
access. 
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1 1 . (Original) A user information management apparatus according to claim 10, wherein 
the apparatus is arranged to determine the security division of the user terminal based on the 
registered number of users of the user terminal. 

12. (Original) A user information management apparatus according to claim 10, wherein 
the apparatus is arranged so that, when the security division falls into a predetermined division 
among said security divisions, and a certification level is lowered, data transmitted from the 
server to the user terminal is deleted before the certification level is changed to be lowered. 

13. (Original) A user information management apparatus according to claim 10, wherein 
the apparatus is arranged so that, when the security division falls into a predetermined division 
among said security divisions, data inputted from the user terminal is automatically and/or 
periodically transmitted to a predetermined work area of the server. 

14. (Currently Amended) A user information management apparatus according to claim 
4- anv one of claims 5 to 7. wherein said transmission control means fiirther comprises a user 
information use criterion storing means for storing a user information use criterion for a data 
requester in advance and a user information providing condition storing means for storing a user 
information providing condition for a data provider in advance, and, when the user information 
use criterion and the user information providing condition are compared with each other, and 
transmission is controlled based on the comparison result, if user information other than that on a 
user determined by the user determination means is contained in data, the user information 
providing condition of the user is obtained, and comparison with the user information use 
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criterion is carried out, thereby determining whether or not transmission is carried out. 

15. (Currently Amended) A user information management method in the user 
information management apparatus constructed at at least one of (a) a server capable of making 
bidirectional communication with a user terminal and (b) the user terminal, the method 
comprising the steps of: 

storage step of holding user information concerning a plurality of users who use the user 
terminal to be associated with a security level; identification step of, when a user makes access to 
the server and an attempt is made by the user to use a predetermined application, identifying the 
user; 

level determining step of, when the user makes access to the server, determining at which 
of a plurality of predetermined certification levels this access is; 

transmission control step of enabling transmission of only the user information at the 
security level and the lower security level than said security level that corresponds to the 
determined level to the user terminal and/or another device among the user information held in 
the storage step; and 

transmission disabling step of, following at least one of conditions (a)an elapse of a 
predetermined period of time and/or an execution of a predetermined operation after 
predetermined user information is enabled to be transmitted by transmission control step, and (b) 
an input of a predetermined instruction from the user, disabling transmission of user information 
at security levels other than the lowest thus enabled to be transmitted. 

16. (Original) A user information management method according to claim 15, wherein 
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said transmission disabling step enables only user information at a security level lower than the 
security level that corresponds to the determined level to be transmitted to the user terminal 
and/or another device. 

17. (Original) A user information management method according to claim 15 or claim 
16, wherein said user identifying step uses at least one of (a) a password inputted by the user at 
the user terminal, (b) ID card information, (c) magnetic card information, (d) fingerprint, (d) 
voiceprint, and (e) iris print of the user which are read by the user terminal. 

1 8. (Currently Amended) A user information management method according to claim 1 5 
or claim 16 , wherein said level determining step determines a predetermined technique employed 
by the user for the purpose of user identification, thereby determining a level. 

1 9. (Currently Amended) A user information management method according to claim 15 
in the user information management apparatus constructed at at least one of (a) a server capable 
of making bidirectional communication with a user terminal and fb) the user terminal, the 
method comprising the steps of: storage step of holding user information concerning a plurality 
of users who use the user terminal to be associated with a security level; identification step of, 
when a user makes access to the server and an attempt is made by the user to use a 
predetermined application, identifying the user: level determining step of, when the user makes 
access to the server, determining at which of a plurality of predetermined certification levels this 
access is: transmission control step of enabling transmission of only the user information at the 
security level and the lower security level than said security level that corresponds to the 
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determined level to the user terminal and/or another device among the user information held in 
the storage step: and transmission disabling step of, following at least one of conditions (a)an 
elapse of a predetermined period of time and/or an execution of a predetermined operation after 
predetermined user information is enabled to be transmitted by transmission control step, and (b) 
an input of a predetermined instruction from the user, disabling transmission of user information 
thus enabled to be transmitted , wherein said user identifying step determines said user based on a 
predetermined instruction from an input device operated by said user at said user terminal, and, 
in this case, said level determining step determines that the certification level is the lowest. 

20. (Currently Amended) A user information management method according to claim 15 
in the user information management apparatus constructed at at least one of (a) a server capable 
of making bidirectional communication with a user terminal and (b) the user terminal, the 
method comprising the steps of: storage step of holding user information concerning a plurality 
of users who use the user terminal to be associated with a security level: identification step of, 
when a user makes access to the server and an attempt is made by the user to use a 
predetermined application, identifying the user: level determining step of, when the user makes 
access to the server, determining at which of a plurality of predetermined certification levels this 
access is: transmission control step of enabling transmission of only the user information at the 
security level and the lower security level than said security level that corresponds to the 
determined level to the user terminal and/or another device among the user information held in 
the storage step: and transmission disabling step of, following at least one of conditions (a)an 
elapse of a predetermined period of time and/or an execution of a predetermined operation after 
predetermined user information is enabled to be transmitted by transmission control step, and (b) 
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an input of a predetermined instruction from the usen disabling transmission of user information 
thus enabled to be transmitted, wherein, if a current certification level of the user is lower than a 
desired certification level required for data acquisition, said transmission control step instructs 
the user to take action required to level up to the required certification level. 

2 1 . (Currently Amended) A user information management method according to claim 15 
in the user information management apparatus constructed at at least one of (a) a server capable 
of making bidirectional communication with a user terminal and Cb) the user terminal the 
method comprising the steps of: storage step of holding user information conceming a plurality 
of users who use the user terminal to be associated with a security level; identification step of, 
when a user makes access to the server and an attempt is made by the user to use a 
predetermined application, identifying the user; level determining step of, when the user makes 
access to the server, determining at which of a plurahty of predetermined certification levels this 
access is; transmission control step of enabling transmission of only the user information at the 
security level and the lower security level than said security level that corresponds to the 
determined level to the user terminal and/or another device among the user information held in 
the storage step; and transmission disabling step of, following at least one of conditions (a)an 
elapse of a predetermined period of time and/or an execution of a predetermined operation after 
predetermined user information is enabled to be transmitted by transmission control step, and (b) 
an input of a predetermined instruction from the user, disabling transmission of user information 
thus enabled to be transmitted, wherein said transmission control step has the step of defining a 
security level specific to said user information and the step of managing said user information for 
said each security level. 
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22. (Currently Amended) A user information management method according to claim 15 
any one of claims 19 to 21. wherein the method is arranged to hold, in the storage step, 
information common to a plurality of users who use the user terminals as group data to be 
associated with a security level. 

23. (Currently Amended) A user information management method according to claim 15 
in the user information management apparatus constructed at at least one of (a) a server capable 
of making bidirectional communication with a user terminal and (b) the user terminal, the 
method comprising the steps of: storage step of holding user information concerning a plurality 
of users who use the user terminal to be associated with a security level: identification step of, 
when a user makes access to the server and an attempt is made by the user to use a 
predetermined application, identifying the user: level determining step of when the user makes 
access to the server, determining at which of a plurality of predetemiined certification levels this 
access is; transmission control step of enabling transmission of only the user information at the 
security level and the lower security level than said security level that corresponds to the 
determined level to the user terminal and/or another device among the user information held in 
the storage step: and transmission disabling step of. following at least one of conditions (a)an 
elapse of a predetermined period of time and/or an execution of a predetermined operation after 
predetermined user information is enabled to be transmitted bv transmission control step, and (b) 
an input of a predetermined instruction from the user, disabling transmission of user information 
thus enabled to be transmitted, wherein the method comprises the step of obtaining, for a set of 
requested data, an index as an ID fi-om a distance between a probability of such an event and 
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data, and then using the obtained value to reconfirm a security. 

24. (Currently Amended) A user information management method according to claim 15 
in the user information management apparatus constructed at at least one of (a) a server capable 
of making bidirectional communication with a user terminal and (h) the user terminal the 
method comprising the steps of: storage step of holding user information conceming a plurality 
of users v^ho use the user terminal to be associated with a security level; identification step of. 
when a user makes access to the server and an attempt is made by the user to use a 
predetermined application, identifying the user; level determining step of> when the user makes 
access to the server, determining at which of a pluraUtv of predetermined certification levels this 
access is; transmission control step of enabling transmission of only the user information at the 
security level and the lower security level than said security level that corresponds to the 
determined level to the user terminal and/or another device among the user information held in 
the storage step; and transmission disabling step of following at least one of conditions (a)an 
elapse of a predetermined period of time and/or an execution of a predetermined operation after 
predetermined user information is enabled to be transmitted by transmission control step, and (b) 
an input of a predetermined instruction fi^om the user, disabling transmission of user information 
thus enabled to be transmitted , wherein the method is arranged so that said plurality of user 
terminals are classified in advance into a plurahty of security divisions, and security division 
determining step is provided, thereby applying access restriction for such each security division 
of the user terminal that has made access. 

25. (Original) A user information management method according to claim 24, wherein 
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the method is arranged to determine the security division of the user terminal based on the 
registered number of users of the user terminal. 

26. (Original) A user information management method according to claim 24, wherein 
the method is arranged so that, when the security division falls into a predetermined division 
among said security divisions, and a certification level is lowered, data transmitted from the 
server to the user terminal is deleted before the certification level is changed to be lowered. 

27. (Original) A user information management method according to claim 24, wherein 
the method is arranged so that, when the security division falls into a predetermined division 
among said security divisions, data inputted from the user terminal is automatically and/or 
periodically transmitted to a predetermined work area of the server. 

28. (Currently Amended) A user information management method according to claim 15 
any one of claims 23 to 27, wherein, a user information use criterion for a data requester is stored 
in advance, and a user information providing condition for a data provider is stored in advance, 
and when the transmission control step fiirther compares the user information use criterion and 
the user information providing condition with each other, so that transmission is controlled based 
on the comparison result, if user information other than that on a user determined by the user 
determination means is contained in data, the user information providing condition of the user is 
obtained, and comparison with the user information use criterion is carried out, thereby 
determining whether or not transmission is carried out. 
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29. (Currently Amended) A recording medium having recorded therein in a computer 
readable state a control program for executing the user information management method in the 
user information management apparatus constructed at at least one of (a) a server capable of 
making bidirectional communication with a user, and (b) the user terminal, the recording 
medium having recorded therein in a computer readable state a control program for executing the 
user information management method comprising the steps of: 

storage step of holding user information concerning a plurality of users who use the user 
terminal to be associated with a security level; 

identification step of, when a user makes access to the server and an attempt is made by 
the user to use a predetermined application, identifying the user; 

level determining step of, when the user makes access to the server, determining at which 
of a plurality of predetermined certification levels this access is; 

transmission control step of enabling transmission of only the user information at the 
security level and the lower security level than said security level that corresponds to the 
determined level to the user terminal and/or another device among the user information held in 
the storage step; and 

transmission disabling step of, after elapse of a predetermined period of time and/or after 
execution of a predetermined operation after predetermined user information is enabled to be 
transmitted by transmission control step, or alternatively, according to a predetermined 
instruction fi-om the user, disabling transmission of user information at security levels other than 
the lowest thus enabled to be transmitted. 

30. (Original) A recording medium having recorded therein in a computer readable state 



1386302A01022206 



16 



4777-7 

a control program for executing the user information management method according to claim 29, 
wherein said transmission disabling step enables transmission of only user information at a 
security level lower than said security level corresponding to said determined level to said user 
terminal and/or another device. 

3 1 . (Original) A recording medium having recorded in a computer readable state a 
control program for executing the user information management method according to claim 29 
or claim 30, wherein said user identifying step uses at least one of (a) a password inputted by the 
user at the user terminal , (b) any one or more of ID card information, (c) magnetic card 
information, (d) fingerprint, (e) voiceprint, and (f) iris print of the user. 

32. (Currently Amended) A recording medium having recorded in a computer readable 
state a control program for executing the user information management method according to 
claim 29 or claim 30 , wherein said level determining step determines a predetermined technique 
employed by the user for the purpose of user identification, thereby determining a level. 

33. (Currently Amended) A recording medium having recorded therein in a computer 
readable state a control program for executing the user information management method 
according to claim 29 in the user information management apparatus constructed at at least one 
of (a) a server capable of making bidirectional conmiunication with a user, and (b) the user 
terminal the recording medium having recorded therein in a computer readable state a control 
program for executing the user information management method comprising the steps of: storage 
step of holding user information concerning a pluralitv of users who use the user terminal to be 
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associated with a security level; identification step of. when a user makes access to the server 
and an attempt is made by the user to use a predetermined application, identifying the user; level 
determining step of. when the user makes access to the server, determining at which of a 
pluraUty of predetermined certification levels this access is; transmission control step of enabling 
transmission of only the user information at the security level and the lower security level than 
said security level that corresponds to the determined level to the user terminal and/or another 
device among the user information held in the storage step; and transmission disabling step of. 
after elapse of a predetermined period of time and/or after execution of a predetermined 
operation after predetermined user information is enabled to be transmitted by transmission 
control step, or altematively, according to a predetermined instruction fi-om the user, disabling 
transmission of user information thus enabled to be transmitted, wherein said user identifying 
step determines said user based on a predetermined instruction fi-om an input device operated by 
said user at said user terminal, and, in this case, said level determining step determines that the 
certification level is the lowest. 

34. (Currently Amended) A recording medium having recorded therein in a computer 
readable state a control program for executing the user information management method 
according to claim 29 in the user information management apparatus constructed at at least one 
of (a) a server capable of making bidirectional communication with a user, and (b) the user 
terminal, the recording medium having recorded therein in a computer readable state a control 
program for executing the user information management method comprising the steps of: storage 
step of holding user information conceming a plurality of users who use the user terminal to be 
associated with a security level; identification step of. when a user makes access to the server 
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and an attempt is made by the user to use a predetermined application, identifying the user: level 
determining step of. when the user makes access to the server, determining at which of a 
plurality of predetermined certification levels this access is; transmission control step of enabling 
transmission of only the user information at the security level and the lower security level than 
said security level that corresponds to the determined level to the user terminal and/or another 
device among the user information held in the storage step: and transmission disabling step of, 
after elapse of a predetermined period of time and/or after execution of a predetermined 
operation after predetermined user information is enabled to be transmitted by transmission 
control step, or altemativelv, according to a predetermined instmction fi'om the user, disabling 
transmission of user information thus enabled to be transmitted , wherein, if a current certification 
level of the user is lower than a desired certification level required for data acquisition, said 
transmission control step instructs the user to take action required to level up to the required 
certification level. 

35. (Currently Amended) A recording medium having recorded therein in a computer 
readable state a control program for executing the user information management method 
according to claim 29 in the user information management apparatus constructed at at least one 
of (a) a server capable of making bidirectional communication with a user, and (h) the user 
terminal, the recording medium having recorded therein in a computer readable state a control 
program for executing the user information management method comprising the steps of: storage 
step of holding user information concerning a plurality of users who use the user terminal to be 
associated with a security level: identification step of, when a user makes access to the server 
and an attempt is made by the user to use a predetermined application, identifying the user: level 
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determining step of, when the user makes access to the server, determining at which of a 
plurality of predetermined certification levels this access is; transmission control step of enabUng 
transmission of only the user information at the security level and the lower security level than 
said security level that corresponds to the determined level to the user terminal and/or another 
device among the user information held in the storage step; and transmission disabling step of, 
after elapse of a predetermined period of time and/or after execution of a predetermined 
operation after predetermined user information is enabled to be transmitted by transmission 
control step, or altematively, according to a predetermined instruction from the user, disabling 
transmission of user information thus enabled to be transmitted, wherein said transmission 
control step has the step of defining a security level specific to said user information and the step 
of managing said user information for said each secxuity level. 

36. (Currently Amended) A recording medium having recorded in a computer readable 
state a control program for executing the user information managing method according to claim 
39 any one of claims 33 to 35 , wherein the recording medium is arranged to hold, in the storage 
step, information common to a plurality of users who use the user terminals as group data to be 
associated with a security level. 

37. (Currently Amended) A recording medium having recorded therein in a computer 
readable state a control program for executing the user information management method 
according to claim 29 in the user information management apparatus constructed at at least one 
of (a) a server capable of making bidirectional conmiunication with a user, and (b) the user 
terminal, the recording medium having recorded therein in a computer readable state a control 
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program for executing the user information management method comprising the steps of: storage 
step of holding user information concerning a plurality of users who use the user terminal to be 
associated with a security level: identification step of when a user makes access to the server 
and an attempt is made by the user to use a predetermined application, identifying the user: level 
determining step of. when the user makes access to the server, determining at which of a 
plurality of predetermined certification levels this access is: transmission control step of enabling 
transmission of only the user information at the security level and the lower security level than 
said security level that corresponds to the determined level to the user terminal and/or another 
device among the user information held in the storage step: and transmission disabling step of. 
after elapse of a predetermined period of time and/or after execution of a predetermined 
operation after predetermined user information is enabled to be transmitted by transmission 
control step, or alternatively, according to a predetermined instruction firom the user, disabling 
transmission of user information thus enabled to be transmitted, wherein the recording medium is 
arranged so that, for a set of requested data, an index as an ID is obtained fi'om a distance 
between a probabihty of such an event and data, and then, the obtained value is used to 
reconfirm a security. 

38. (Currently Amended) A recording medium having recorded therein in a computer 
readable state a control program for executing the user information management method 
according to claim 29 in the user information management apparatus constructed at at least one 
of (a) a server capable of making bidirectional communication with a user, and fb) the user 
terminal, the recording medium having recorded therein in a computer readable state a control 
program for executing the user information management method comprising the steps of: storage 



1386302A01 022206 



21 



4777-7 

step of holding user information concerning a plurality of users who use the user terminal to be 
associated with a security level; identification step of, when a user makes access to the server 
and an attempt is made by the user to use a predetermined application, identifying the user: level 
determining step of. when the user makes access to the server, determining at which of a 
plurality of predetermined certification levels this access is: transmission control step of enabling 
transmission of only the user information at the security level and the lower security level than 
said security level that corresponds to the determined level to the user terminal and/or another 
device among the user information held in the storage step; and transmission disabling step of, 
after elapse of a predetermined period of time and/or after execution of a predetermined 
operation after predetermined user information is enabled to be transmitted by transmission 
control step, or alternatively, according to a predetermined instruction fi-om the user, disabling 
transmission of user information thus enabled to be transmitted, wherein the recording medium is 
arranged so that said plurality of user terminals are classified in advance into a plurality of 
security divisions, and security division determining step is provided, thereby applying access 
restriction for such each security division of the user terminal that has made access. 

39. (Original) A recording medium having recorded in a computer readable state a 
control program for executing the user information managing method according to claim 38, 
wherein the recording medivun is arranged to determine the security division of the user terminal 
based on the registered nxmiber of users of the user terminal. 

40. (Original) A recording medium having recorded in a computer readable state a 
control program for executing the user information managing method according to claim 38, 
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wherein the recording medium is arranged so that, when the security division falls into a 
predetermined division among said security divisions, and a certification level is changed to be 
lowered, data transmitted firom the server to the user terminal is deleted before the certification 
level is lowered. 

41 . (Original) A recording medium having recorded in a computer readable state a 
control program for executing the user information managing method according to claim 38, 
wherein, when the security division falls into a predetermined division among said security 
divisions, data inputted fi"om the user terminal is automatically and/or periodically transmitted to 
a predetermined work area of the server. 

42. (Currently Amended) A recording medium having recorded in a computer readable 
state a control program for executing the user information managing method according to claim 
29 anv one of claims 37 to 4K wherein the recording medium is arranged so that, a user 
information use criterion for a data requester is stored in advance, and a user information 
providing condition for a data provider is stored in advance, and when the user information use 
criterion and the user information providing condition are compared with each other, and 
transmission is controlled based on the comparison result, if user information other than that on a 
user determined by the user determination means is contained in data, the user information 
providing condition of the user is obtained, and comparison with the user information use 
criterion is carried out, thereby determining whether or not transmission is carried out. 

43. (Original) A user information management apparatus comprising: 
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an access accepting section for accepting data access; 

an access privilege determining section for determining the presence or absence of access 
privilege relevant to data on the access accepted at the access accepting section; and 

an access management section for making a change in access privilege relevant to data on 
the access accepted at the access accepting section. 

44. (Original) A user information management apparatus according to claim 43, wherein 
the access privilege determining section determines the presence or absence of access privilege 
based on an access privilege table in which data and access privilege are associated with each 
other. 

45. (Original) A user information management apparatus according to claim 43, wherein 
the access privilege determining section determines the presence or absence of access privilege 
based on the access privilege described in data. 

46. (Original) A user information management apparatus according to claim 43, wherein 
the access management section has an access privilege change information output means for 
outputting access privilege change information indicative of the changed access privilege. 

47. (Original) A user information management apparatus according to claim 46, wherein 
the access privilege determining section has access privilege change information acquiring 
means for acquiring access privilege change information from the access privilege change 
information output means. 



1386302A01022206 



24 



I > 



48. (Original) A user information management apparatus according to claim 46, wherein 
the access accepting section accepts an access from a device, and the access privilege change 
information output means transmits the access privilege change information to said device. 

49. (Original) A user information management apparatus according to claim 43, further 
comprising an access privilege change condition acquiring section for acquiring a condition for 
changing access privilege, 

50. (Original) A user information management apparatus according to any one of claims 
43 to 47, wherein a change in access privilege at the access management section is a change in 
access level privilege within the range of data that can be accessed. 

5 1 . (Original) A user information management apparatus according to any one of claims 
43 to 47, wherein the data to be accessed is classified by the owners, and a change in access 
privilege is a change in access privilege to data of another owner associated with the accessed 
data. 

52. (Original) A user information management apparatus according to claim 51, wherein 
the access management section is restored to the original access privilege after the completion of 
processing by said access change. 

53. (Original) A user information management apparatus according to any one of claims 
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43 to 47, wherein, when it is determined that an access at the access accepting section is 
provided without privilege at the access privilege determining section, there is further provided 
an certification acquiring section that requests acquisition of access privilege. 

54. (Original) A user information management apparatus according to claim 49, wherein 
a condition for changing said access privilege is at least one of: (a) a no access continuation time, 
(b) data access count, (c) an instruction fi-om an accessing person, (d) an instruction fi-om an 
operating system, (e) an instruction from an application program, (f) an elapsed time after 
starting access, (g) time information, (h) access rejection count, (i) an elapsed time after 
changing access privilege, and (j) a combination of two or more thereof 

55. (Original) A user information management program causing a computer to execute 
the steps of: 

access accepting step of accepting data access; 

access privilege determining step of determining the presence or absence of access 
privilege to the access data accepted in the access accepting step; and 

access management step of changing the access privilege relevant to data on the access 
accepted in the access accepting step. 

56. (Original) A user information management program according to claim 55, the 
program causing a computer to execute the access privilege change information output step of 
outputting access privilege change information that is information indicative of the changed 
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access privilege in the access management step. 

57. (Original) A user information management program according to claim 55, the 
program causing a computer to execute the access privilege change condition acquiring step of 
acquiring a condition for changing access privilege. 
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